fix: Use library config for Windows OpenSSL

This commit is contained in:
Nick Bolton 2024-10-01 08:52:10 +01:00
parent 31e1c8da84
commit 2d732a4b9d
5 changed files with 18 additions and 124 deletions

View file

@ -147,7 +147,7 @@
<File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/> <File Id="OpenSSLDll2" Source="$(var.OpenSslDllDir)/libssl-3.dll"/>
<?endif ?> <?endif ?>
<File Source="$(var.OpenSslExeDir)/openssl.exe"/> <File Source="$(var.OpenSslExeDir)/openssl.exe"/>
<File Source="$(var.ResPath)/openssl/deskflow.conf"/> <File Source="$(var.OpenSslExeDir)/openssl.cnf"/>
</Component> </Component>
</ComponentGroup> </ComponentGroup>
</Fragment> </Fragment>

View file

@ -1,65 +0,0 @@
#
# Deskflow OpenSSL configuration file.
# Used for generation of certificate requests.
#
dir = .
[ca]
default_ca = CA_default
[CA_default]
serial = $dir/serial
database = $dir/certindex.txt
new_certs_dir = $dir/certs
certificate = $dir/cacert.pem
private_key = $dir/private/cakey.pem
default_days = 365
default_md = sha256
preserve = no
email_in_dn = no
nameopt = default_ca
certopt = default_ca
policy = policy_match
[policy_match]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional
[req]
default_bits = 1024 # Size of keys
default_keyfile = key.pem # name of generated keys
default_md = sha256 # message digest algorithm
string_mask = nombstr # permitted characters
distinguished_name = req_distinguished_name
req_extensions = v3_req
[req_distinguished_name]
0.organizationName = Organization Name (company)
organizationalUnitName = Organizational Unit Name (department, division)
emailAddress = Email Address
emailAddress_max = 40
localityName = Locality Name (city, district)
stateOrProvinceName = State or Province Name (full name)
countryName = Country Name (2 letter code)
countryName_min = 2
countryName_max = 2
commonName = Common Name (hostname, IP, or your name)
commonName_max = 64
0.organizationName_default = My Company
localityName_default = My Town
stateOrProvinceName_default = State or Providence
countryName_default = US
[v3_ca]
basicConstraints = CA:TRUE
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer:always
[v3_req]
basicConstraints = CA:FALSE
subjectKeyIdentifier = hash

View file

@ -138,11 +138,6 @@ void SettingsDialog::on_m_pPushButtonTlsCertPath_clicked() {
qDebug("no tls certificate file at: %s", qUtf8Printable(fileName)); qDebug("no tls certificate file at: %s", qUtf8Printable(fileName));
} }
} }
updateTlsRegenerateButton();
}
void SettingsDialog::on_m_pComboBoxTlsKeyLength_currentIndexChanged(int) {
updateTlsRegenerateButton();
} }
void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() { void SettingsDialog::on_m_pPushButtonTlsRegenCert_clicked() {
@ -277,18 +272,6 @@ bool SettingsDialog::isClientMode() const {
return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client; return m_coreProcess.mode() == deskflow::gui::CoreProcess::Mode::Client;
} }
void SettingsDialog::updateTlsRegenerateButton() {
const auto writable = m_appConfig.isActiveScopeWritable();
const auto keyLength = m_pComboBoxTlsKeyLength->currentText().toInt();
const auto path = m_pLineEditTlsCertPath->text();
const auto keyChanged = m_appConfig.tlsKeyLength() != keyLength;
const auto pathChanged = m_appConfig.tlsCertPath() != path;
const auto tlsEnabled = m_pCheckBoxEnableTls->isChecked();
m_pPushButtonTlsRegenCert->setEnabled(
writable && tlsEnabled && (keyChanged || pathChanged));
}
void SettingsDialog::updateKeyLengthOnFile(const QString &path) { void SettingsDialog::updateKeyLengthOnFile(const QString &path) {
TlsCertificate ssl; TlsCertificate ssl;
if (!QFile(path).exists()) { if (!QFile(path).exists()) {
@ -337,7 +320,5 @@ void SettingsDialog::updateControls() {
m_pLineEditLogFilename->setEnabled(writable && logToFile); m_pLineEditLogFilename->setEnabled(writable && logToFile);
m_pButtonBrowseLog->setEnabled(writable && logToFile); m_pButtonBrowseLog->setEnabled(writable && logToFile);
updateTlsControlsEnabled();
updateTlsRegenerateButton();
updateTlsControls(); updateTlsControls();
} }

View file

@ -53,7 +53,6 @@ private slots:
void on_m_pButtonBrowseLog_clicked(); void on_m_pButtonBrowseLog_clicked();
void on_m_pRadioSystemScope_toggled(bool checked); void on_m_pRadioSystemScope_toggled(bool checked);
void on_m_pPushButtonTlsCertPath_clicked(); void on_m_pPushButtonTlsCertPath_clicked();
void on_m_pComboBoxTlsKeyLength_currentIndexChanged(int index);
void on_m_pPushButtonTlsRegenCert_clicked(); void on_m_pPushButtonTlsRegenCert_clicked();
void on_m_pCheckBoxServiceEnabled_toggled(bool checked); void on_m_pCheckBoxServiceEnabled_toggled(bool checked);

View file

@ -18,7 +18,6 @@
#include "TlsCertificate.h" #include "TlsCertificate.h"
#include "TlsFingerprint.h" #include "TlsFingerprint.h"
#include "gui/paths.h"
#include <QCoreApplication> #include <QCoreApplication>
#include <QDir> #include <QDir>
@ -32,13 +31,11 @@ static const char *const kCertificateSubjectInfo = "/CN=Deskflow";
#if defined(Q_OS_WIN) #if defined(Q_OS_WIN)
static const char *const kWinOpenSslDir = "OpenSSL"; static const char *const kWinOpenSslDir = "OpenSSL";
static const char *const kWinOpenSslBinary = "openssl.exe"; static const char *const kWinOpenSslBinary = "openssl.exe";
static const char *const kConfigFile = "deskflow.conf"; static const char *const kConfigFile = "openssl.cnf";
#elif defined(Q_OS_UNIX) #elif defined(Q_OS_UNIX)
static const char *const kUnixOpenSslCommand = "openssl"; static const char *const kUnixOpenSslCommand = "openssl";
#endif #endif
using namespace deskflow::gui;
#if defined(Q_OS_WIN) #if defined(Q_OS_WIN)
namespace deskflow::gui { namespace deskflow::gui {
@ -90,61 +87,43 @@ using namespace deskflow::gui;
TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {} TlsCertificate::TlsCertificate(QObject *parent) : QObject(parent) {}
bool TlsCertificate::runTool(const QStringList &args) { bool TlsCertificate::runTool(const QStringList &args) {
QString program;
#if defined(Q_OS_WIN) #if defined(Q_OS_WIN)
program = openSslWindowsBinary(); const auto program = openSslWindowsBinary();
#else #else
program = kUnixOpenSslCommand; const auto program = kUnixOpenSslCommand;
#endif #endif
QStringList environment; QStringList environment;
#if defined(Q_OS_WIN) #if defined(Q_OS_WIN)
auto openSslDir = QDir(openSslWindowsDir()); const auto openSslDir = QDir(openSslWindowsDir());
auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile)); const auto config = QDir::cleanPath(openSslDir.filePath(kConfigFile));
if (!QFile::exists(config)) {
qDebug("openssl config file not found: %s", qUtf8Printable(config));
// if the expected production file location doesn't exist, try the dev path.
config = QDir::cleanPath(QString("res/openssl/%1").arg(kConfigFile));
// if it still isn't there, then there's something seriously wrong.
if (!QFile::exists(config)) {
qFatal() << "openssl config file not found: " << config;
}
}
environment << QString("OPENSSL_CONF=%1").arg(config); environment << QString("OPENSSL_CONF=%1").arg(config);
#endif #endif
QProcess process;
process.setEnvironment(environment);
for (const auto &envVar : environment) {
qDebug("set env var: %s", qUtf8Printable(envVar));
}
qDebug( qDebug(
"running: %s %s", qUtf8Printable(program), "running: %s %s", qUtf8Printable(program),
qUtf8Printable(args.join(" "))); qUtf8Printable(args.join(" ")));
QProcess process;
for (const auto &envVar : environment) {
qDebug("setting env var %s", qUtf8Printable(envVar));
}
process.setEnvironment(environment);
process.start(program, args); process.start(program, args);
bool success = process.waitForStarted(); bool success = process.waitForStarted();
QString stderrOutput; QString toolStderr;
if (success && process.waitForFinished()) { if (success && process.waitForFinished()) {
m_toolStdout = process.readAllStandardOutput().trimmed(); m_toolStdout = process.readAllStandardOutput().trimmed();
stderrOutput = process.readAllStandardError().trimmed(); toolStderr = process.readAllStandardError().trimmed();
} }
if (int code = process.exitCode(); !success || code != 0) { if (int code = process.exitCode(); !success || code != 0) {
qDebug( qDebug("openssl failed with code %d: %s", code, qUtf8Printable(toolStderr));
"openssl failed with code %d: %s", code, qUtf8Printable(stderrOutput));
qCritical( qCritical(
"failed to generate TLS certificate:\n\n%s", "failed to generate tls certificate:\n\n%s",
qUtf8Printable(stderrOutput)); qUtf8Printable(toolStderr));
return false; return false;
} }